Name and contact person of the party responsible in accordance with Article 4 Para. 7 GDPR
Center of Excellence in Orthopaedic Surgery
Ensuring the confidentiality of the personal data you provide and protecting it from unauthorised access is our top priority. This is why we take extreme care and use the latest security standards to ensure the maximum protection of your personal data.As a company under private law, we are subject to the provisions of the European General Data Protection Regulation (GDPR) and the regulations of the Federal Data Protection Act (BDSG). We have taken technical and organisational measures that ensure that both we and our external service providers observe data protection regulations.
1. Personal data
"Personal data" means all information relating to an identified or identifiable natural person (hereinafter referred to as the "person concerned"); a natural person is considered identifiable if that person can be identified directly or indirectly, especially by means of allocation to an identification such as a name, an identity number, location data, an online ID, or to one or more special characteristics that are an expression of the physical, physiological, genetic, mental, economic, cultural or social identity of this natural person.
"Processing" means each operation executed with or without the help of automated procedures or any such series of operations in connection with personal data such as the collection, recording, organisation, arrangement, storage, modification or change, export, query, use, disclosure by means of transmission, dissemination or another form of provision, comparison or linking, restriction, deletion or destruction.
3. Restriction of processing
"Restriction of processing" means the marking of stored personal data with the objective of restricting its future processing.
"Profiling" means any kind of automated processing of personal data that consists of this personal data being used to assess certain personal aspects relating to a natural person, in particular to analyse or predict aspects regarding their work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or change of location of this natural person.
"Pseudonymisation" means the processing of personal data in a way that the personal data can no longer be assigned to a specific person concerned without the addition of additional information, provided that this additional information is kept separate and is subject to technical and organizational measures that ensure that the personal data cannot be assigned to an identified or identifiable natural person.
6. File system
"File system" is each structured collection of personal data that is accessible according to certain criteria, regardless of whether this collection is maintained centrally, decentrally, or arranged according to functional or geographical factors.
7. Party responsible
"Party responsible" is a natural or legal person, authority, agency or other body which, alone or together with others, decides on the purpose and means of the processing of personal data; if the purpose and means of this processing are specified by European Union law or the law of the Member States, the party responsible or rather the specific conditions of its appointment in accordance with European Union law or the law of the Member States can be provided for.
8. Data processor
"Data processor" is a natural or legal person, authority, agency or other body that processes personal data on behalf of the party responsible.
"Recipient" refers to a natural or legal person, public authority, agency or other body to whom person data is disclosed, regardless of whether or not this is a third party. Authorities who may receive personal data as part of a specific request for investigation according to European Union law or the law of the Member States do not count as a recipient, however; this data is processed by the named authorities in accordance with the applicable data protection regulations in accordance with the purposes of the processing.
10. Third party
"Third party" is a natural or legal person, authority, agency or other body apart from the person concerned, the party responsible, the data processor and the persons who are authorised to process the personal data under the direct responsibility of the party responsible or the data processor.
"Consent" granted by the person concerned means each statement of intent that is submitted for the specific case in an informed and unequivocal way in the form of a statement or another clearly confirming action, with which the person concerned intimates that he or she agrees to the processing of the personal data relating to that person.
The processing of personal data is lawful only if a legal basis exists for its processing. The legal basis for the processing according to Article 6 Para. 1 (a) – (f) GDPR can be in particular:
(1) The following information relates to the collection of personal data during the use of our website. Personal data is, for example: name, address, e-mail addresses, user behaviour.(2) If you make contact with us via e-mail or by using a contact form, the data you provide (your e-mail address or your name and telephone number) is stored by us so that we can answer your questions. We will delete the data that is generated in this context once its storage is no longer necessary, or its processing is restricted if there is a legal obligation to retain the data.Collection of personal data when you visit our websiteIf you use our website purely for information purposes, that is, if you do not register on it or send us information otherwise, we collect only the personal data that is transmitted to our server by your browser. If you would like to view our website, we collect the following data that is technically necessary for us to present our website to you and to ensure its stability and security (the legal basis is the first sentence of Art. 6 Para. 1 (f) GDPR):
Additional functions and offerings of our website(1) In addition to the use of our website purely for information purposes, we offer various services that you may be interested in using. To do this, you usually have to specify personal data which we use for providing the relevant service and to which the previously mentioned principles for data processing apply. (2) We sometimes use external service providers for processing your data. These have been carefully selected and commissioned by us, are bound by our instructions, and are monitored on a regular basis.(3) We can also forward your personal data to third parties if we offer sale campaigns, competitions, contract conclusions or similar services together with partners. You will receive more information about this when you provide your personal data or below in the description of the offer.(4) If our service providers or partners are based in a country outside of the European Economic Area (EEA), we will inform you about the consequences of this in the description of the offer.
Our offering is intended for adults only. Persons under 18 years old should not pass personal data to us without the agreement of their parents or guardians.
(1) Withdrawal of consent
If the processing of personal data is based on consent that was granted, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of consent-based processing carried out up to the point of withdrawal.You can contact us at any time to exercise your right of withdrawal.
(2) Right to confirmation
You have the right to request confirmation from the party responsible regarding whether we process the personal data relating to you. You can request the confirmation at any time by using the contact details mentioned above.
(3) Right to information
If personal data is processed, you can demand information about this personal data and the following information at any time:
If personal data is transmitted to a third country or to an international organisation, you have the right to be informed about the appropriate warranties in accordance with Article 46 GDPR in connection with the transmission. We provide a copy of the personal data that is the subject of the processing. For all other copies that you request, we can demand an appropriate charge based on administrative costs. If you make the request electronically, the information has to be provided in a common electronic format unless indicated otherwise. The right to receive a copy in accordance with Paragraph 3 must not affect the rights and freedoms of other persons.
(4) Right to correction
You have the right to request from us the immediate correction of personal data relating to you that is incorrect. Taking the purpose of the processing into account, you have the right to request the completion of incomplete personal data including by means of a supplementary statement.
(5) Right to deletion ("right to be forgotten")
You have the right to request the party responsible to delete personal data relating to you with immediate effect and we are obligated to delete personal data with immediate effect if one of the following reasons applies:
If the party responsible has disclosed the personal data and if the party responsible is obligated to its deletion in accordance with Paragraph 1, then taking into account the available technology and the implementation costs, the party responsible takes appropriate measures for informing the party responsible for data processing who processes the personal data that a person concerned has requested them to delete all links to this personal data, or copies or replications of this personal data.The right to deletion ("right to be forgotten") does not exist if the processing is required:
(6) Right to restriction of processing
You have the right to request the restriction of the processing of your personal data if one of the following prerequisites applies:
If the processing was restricted in accordance with the prerequisites named above, then this personal data – apart from its storage – is processed only with the consent of the person concerned or to assert, exercise or defend legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest of the European Union or a Member State.To assert the right to restriction of processing, the relevant person can contact us at any time by using the contact details specified above.
(7) Right to data portability
You have the right to obtain the personal data relating to you that you have provided to us in a structured, common and machine-readable format, and you have the right to transfer this data to a different party responsible without any obstacle from the party responsible to whom the personal data was provided, if:
When exercising the right to data portability in accordance with Paragraph 1, you have the right to effect the direct transfer of personal data from one party responsible to another if this is technically feasible. The exercise of this right to data portability does not affect the right to deletion ("right to be forgotten"). This right does not apply to processing that is necessary for the performance of a task that is in the public interest, or in the exercise of official authority that was vested in the party responsible.
(8) Right to object
You have the right to object at any time to the processing of personal data relating to you resulting from your personal situation, which is based on Article 6 Paragraph 1 (e) or (f) GDPR; this also applies to profiling based on these provisions. The party responsible will no longer process your personal data unless it can demonstrate compelling legitimate reasons that are worth protecting for the processing that the interests, rights and freedoms of the person concerned, or the processing serves to establish, exercise or defend legal claims.If personal data is processed for the purpose of direct advertising, then you have the right to object at any time to the processing of personal data relating to you for the purpose of this type of advertising; this also applies to profiling if it is related to such direct advertising. If you object to the processing for purposes of direct advertising, the personal data will no longer be processed for these purposes.In connection with the use of the services of the information society, regardless of Guideline 2002/58/EC, you can exercise your right to object by means of automated processes with which technical specifications are used.You have the right to object for reasons resulting from your particular situation to the relevant processing of personal data relating to you that takes place for scientific or historic research purposes, or for statistical purposes in accordance with Article 89 Paragraph 1, unless the processing is required to fulfil a task in the public interest.You can exercise your right to object at any time by contacting the respective party responsible.
(9) Automated decisions in individual cases including profiling
You have the right not to be subject to a decision that was based exclusively on automated processing – including profiling – that has a legal effect on you or similarly impairs you considerably. This does not apply if the decision:
The party responsible takes appropriate measures to protect the rights and freedom and the legitimate interests of the person concerned, to which at least the right to obtain intervention by a person on the part of the party responsible, to presenting their case, and the right to challenging the decision belongs.The person concerned can execute this right at any time by contacting the respective party responsible.
(10) Right to complain to a supervisory authority
Irrespective of the provision of another administrative or legal judicial remedy, you also have the right to complain to a supervisory authority, especially in the Member State of your residence, your workplace or the location of the alleged infringement if the person concerned believes that the processing of the personal data relating to them violates this regulation.
(11) Right to effective judicial remedy
Irrespective of an available administrative or non-judicial remedy, including the right to complain to a supervisory authority in accordance with Article 77 GDPR, you have the right to effective judicial remedy if you believe that your rights based on this regulation were violated as a result of the processing of your personal data that is not in line with these regulations.